L
linuzt
Grünschnabel
Hallo,
in mein System ist ein Rootkit eingedrungen,
mit abgehaengter Festplatte habe ich mit PartedMagic Live gebootet und
Rkhunter und Chrootkit laufen lassen folgende Resultate.
./chkrootkit -q zeigt mir
lsof -i
cat /proc/1/maps
rkhunter -c zeigt
tail -f /var/log/wtmp zeigt
Sowas habe ich bis jetzt noch nicht erlebt.
kA wo sich der eingenistet hat, vll im VGA ROM?
in mein System ist ein Rootkit eingedrungen,
mit abgehaengter Festplatte habe ich mit PartedMagic Live gebootet und
Rkhunter und Chrootkit laufen lassen folgende Resultate.
./chkrootkit -q zeigt mir
Code:
Checking `basename'... INFECTED
unknown shell '%s', assuming bash
Checking `date'... INFECTED
Checking `du'... INFECTED
Checking `dirname'... INFECTED
Checking `echo'... INFECTED
Checking `env'... INFECTED
can't exec ./strings-static, Checking `login'... INFECTED
Checking `netstat'... INFECTED
Checking `passwd'... INFECTED
Checking `ps'... INFECTED
Checking `traceroute'... INFECTED
strings: w: No such file or directory
strings: write: No such file or directory
ls: write: No such file or directory
/usr/lib/.directory
/lib/unionfs/usr/bin/.directory
/lib/unionfs/usr/bin/clone/.directory
/lib/unionfs/usr/lib/.directory
/lib/unionfs/usr/sbin/.directory
/lib/unionfs/usr/share/icons/hicolor/16x16/actions/.directory
/lib/unionfs/usr/share/icons/hicolor/24x24/devices/.directory
/lib/unionfs/usr/share/icons/hicolor/48x48/actions/.directory
/lib/unionfs/usr/share/icons/hicolor/48x48/apps/.directory
/lib/unionfs/usr/share/icons/hicolor/48x48/categories/.directory
/lib/unionfs/usr/share/icons/hicolor/48x48/devices/.directory
/lib/unionfs/usr/share/icons/hicolor/48x48/mimetypes/.directory
/lib/unionfs/usr/share/icons/hicolor/48x48/misc/.directory
/lib/unionfs/usr/share/icons/hicolor/48x48/stock/.directory
/lib/unionfs/usr/share/lxpanel/images/.directory
/lib/unionfs/usr/share/pixmaps/.directory
Warning: /sbin/init INFECTED
not tested: can't exec
not tested: can't exec ./ifpromisc
not tested: can't exec ./chkwtmp
not tested: can't exec ./chklastlog
not tested: can't exec ./chkutmp
lsof -i
Code:
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
rpc.statd 2838 root 6u IPv4 10088 UDP *:894
rpc.statd 2838 root 8u IPv4 10096 UDP *:49924
rpc.statd 2838 root 9u IPv4 10099 TCP *:41461 (LISTEN)
rpc.rquot 2842 root 3u IPv4 10114 UDP *:899
rpc.rquot 2842 root 4u IPv4 10120 TCP *:902 (LISTEN)
rpc.mount 2857 root 3u IPv4 10221 UDP *:48625
rpc.mount 2857 root 4u IPv4 10226 TCP *:46557 (LISTEN)
sshd 3122 root 3u IPv4 11683 TCP *:ssh (LISTEN)
sshd 3122 root 4u IPv6 11686 TCP *:ssh (LISTEN)
cat /proc/1/maps
Code:
08048000-080bc000 r-xp 00000000 00:0d 1676 /bin/busybox
080bc000-080bd000 rwxp 00074000 00:0d 1676 /bin/busybox
080bd000-080e0000 rwxp 00000000 00:00 0 [heap]
b760f000-b7610000 rwxp 00000000 00:00 0
b7610000-b777b000 r-xp 00000000 00:0d 2246 /lib/libc-2.11.1.so
b777b000-b777c000 ---p 0016b000 00:0d 2246 /lib/libc-2.11.1.so
b777c000-b777e000 r-xp 0016b000 00:0d 2246 /lib/libc-2.11.1.so
b777e000-b777f000 rwxp 0016d000 00:0d 2246 /lib/libc-2.11.1.so
b777f000-b7782000 rwxp 00000000 00:00 0
b7782000-b77a9000 r-xp 00000000 00:0d 2252 /lib/libm-2.11.1.so
b77a9000-b77aa000 r-xp 00026000 00:0d 2252 /lib/libm-2.11.1.so
b77aa000-b77ab000 rwxp 00027000 00:0d 2252 /lib/libm-2.11.1.so
b77ab000-b77ac000 rwxp 00000000 00:00 0
b77ac000-b77ca000 r-xp 00000000 00:0d 2242 /lib/ld-2.11.1.so
b77ca000-b77cb000 r-xp 0001e000 00:0d 2242 /lib/ld-2.11.1.so
b77cb000-b77cc000 rwxp 0001f000 00:0d 2242 /lib/ld-2.11.1.so
bfb3a000-bfb3d000 rw-p 00000000 00:00 0 [stack]
ffffe000-fffff000 r-xp 00000000 00:00 0 [vdso]
rkhunter -c zeigt
Code:
[01:54:21] Warning: Checking for prerequisites [ Warning ]
[01:54:21] No output from the 'lsattr' command - all file immutable-bit checks will be skipped.
[01:57:32] Warning: Checking for possible rootkit strings [ Warning ]
[01:57:32] Found string 'sendmail' in file '//bin/login'. Possible rootkit: Ambient (ark) Rootkit
[01:57:42] Performing trojan specific checks
[01:57:43] Info: Starting test name 'trojans'
[01:57:43] Info: Using inetd configuration file '/etc/inetd.conf'
[01:57:43] Checking for enabled inetd services [ Warning ]
[01:57:43] Warning: Found enabled inetd service: echo
[01:57:43] Warning: Found enabled inetd service: echo
[01:57:43] Warning: Found enabled inetd service: daytime
[01:57:43] Warning: Found enabled inetd service: daytime
[01:57:43] Warning: Found enabled inetd service: time
[01:57:43] Warning: Found enabled inetd service: time
[01:57:43] Warning: Found enabled inetd service: telnet
Code:
[13:36:18] Checking for syslog configuration file [ Warning ]
[13:36:19] Warning: The syslog daemon is running, but no configuration file can be found.
tail -f /var/log/wtmp zeigt
Code:
9
tty11LOGIN9
��0<9
tty11root9
��0<�pts/0/0root:0��0<[�9pts/0/0root��0<�pts/1/1root:0z1<�0�pts/2/2root:0�1<��
�pts/2/2root:01<�F, pts/2/2root�1<�
pts/2/2root-1<�pts/3/3root:0�1<�epts/3/3root�1<Y��pts/3/3root:0�1<'�pts/2/�pts/2/2root:0!�1<.
Sowas habe ich bis jetzt noch nicht erlebt.
kA wo sich der eingenistet hat, vll im VGA ROM?